QID 980820
QID 980820: Java (maven) Security Update for org.apache.jena:jena-core (GHSA-7rp6-w7mg-h8rw)
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7rp6-w7mg-h8rw for updates pertaining to this vulnerability.
Vendor References
- GHSA-7rp6-w7mg-h8rw -
github.com/advisories/GHSA-7rp6-w7mg-h8rw
CVEs related to QID 980820
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7rp6-w7mg-h8rw | org.apache.jena:jena-core |
|